Ridgeline Grid’s resilience budget can’t cover every asset e…

Ridgeline Grid’s resilience budget can’t cover every asset equally. The resilience lead insists on ranking assets — this field controller before that logging server, this substation before that back-office report — rather than spreading detection, reaction, and recovery investment evenly across everything the company owns. A director calls this unfair triage. Is the resilience lead’s approach the right one?

Ridgeline Grid’s security team and its operations team are d…

Ridgeline Grid’s security team and its operations team are drafting the substation dashboard’s requirements separately, and both claim “availability” as their own requirement. Security frames it as one leg of the confidentiality-integrity-availability triad they’re responsible for; operations frames it as scheduling when users can access the dashboard. A junior analyst is told to pick one team’s framing and drop the requirement from the other’s document. Is that the right call?

Ridgeline Grid’s command-processing service starts receiving…

Ridgeline Grid’s command-processing service starts receiving more substation commands per second than it was provisioned for during a regional storm. Rather than crashing outright, it’s supposed to do something graceful. Which of the following are legitimate responses an efficiency requirement should specify for this situation? (Select all that apply.)

Ridgeline Grid’s substation-monitoring platform has an excel…

Ridgeline Grid’s substation-monitoring platform has an excellent engineering record: redundant hardware, a low defect rate, and 99.9% uptime over three years. At a design review, a senior engineer argues that adding detection and recovery machinery for storm-related outages would be wasted effort, because “a system this well built doesn’t fail.” What is the strongest argument against that position?

Ridgeline Grid’s operations team is defining availability re…

Ridgeline Grid’s operations team is defining availability requirements for the substation dashboard. Two different numbers come up in the discussion: “we can tolerate at most two unplanned interruptions a month,” and, separately, “any interruption has to be resolved within three hours.” A junior analyst treats these as two ways of saying the same requirement. Why is that wrong?

Ridgeline Grid’s original substation-monitoring software has…

Ridgeline Grid’s original substation-monitoring software has a hard-coded limit of 200 simultaneous sensor connections, written directly into the source code. As the company adds substations, operators now have to file a change request and wait for a code change and redeploy every time the limit needs raising. A capacity-planning consultant recommends externalizing that limit into a configuration file operators can edit directly. What NFR-driven technique does this recommendation illustrate?

Nordholm Systems’ security lead pulls together data across t…

Nordholm Systems’ security lead pulls together data across the company’s dozen agile teams and finds a pattern that puzzles her: activities the teams use most often are, on average, rated by the very engineers using them as only moderately impactful on security — while some activities used far less often are rated as highly impactful. A colleague asks what would cause usage rates and perceived impact to diverge like that. What best explains the divergence?

A Nordholm Systems engineer proposes dropping fuzz testing f…

A Nordholm Systems engineer proposes dropping fuzz testing from the verification checklist, pointing out it’s used far less than almost anything else the team does. Before agreeing, the security lead checks how engineers rate fuzz testing’s impact when they do use it — and finds it rated meaningfully more impactful than dynamic analysis, a much more similar-sounding activity that also sees low use. What best explains fuzz testing’s rare use despite its comparatively strong impact rating?

Trellis Health’s new engineering director assumes that if no…

Trellis Health’s new engineering director assumes that if nobody explicitly writes down a security or reliability requirement, the development team will naturally build the system to be reasonably secure and reliable anyway, since “that’s just good engineering.” True or False: this assumption holds up.